Audit every firewall, from configuration, not guesswork.
SAMURAI is a self-hosted firewall audit tool that reads configuration state directly from the device: security policies, NAT, objects, and VPNs across Palo Alto, FortiGate, Cisco FMC/FTD and ASA, and Juniper SRX. It flags shadowed, redundant, and overly broad rules, computes what each rule really permits, and attributes every configuration change to the admin who made it, so a firewall configuration audit becomes an export instead of a fire drill.
Updated July 2026
What it audits
Rule hygiene findings
Shadowed, redundant, and overly broad rules flagged automatically across the whole rule base, the findings auditors look for first.
Effective access
What each rule actually permits end to end, with address and service objects resolved recursively and NAT applied, not just what the rule text says.
Change attribution
Every policy change detected from real device state and attributed to an admin, so who changed what and when has a documented answer.
Configuration audit trail
Snapshot history you can diff between any two points in time, catching changes that never wrote an audit-log entry.
Multi-vendor coverage
One audit across Palo Alto, FortiGate, Cisco FMC/FTD/ASA, and Juniper SRX, plus ACL visibility on routers, switches, and ACI fabrics.
Exportable evidence
Any table exports to CSV, XLSX, HTML, or PDF: the rule inventory, hygiene findings, and change timeline auditors ask for.
Configuration audit vs log-based reporting
A firewall audit answers what the rules are, whether they are clean, and who changed them. Those are configuration questions, not traffic questions, so log-based reporting tools answer the wrong half.
Data source
SAMURAI
Configuration state read from the device
Log-based reporting tools
Syslog and traffic logs
What the audit shows
SAMURAI
Rules, hygiene, effective access, and who changed what
Log-based reporting tools
What traffic passed or was denied
Change accountability
SAMURAI
Every change attributed to an admin
Log-based reporting tools
Not the focus of log reporting
Scope
SAMURAI
Firewalls plus routers, switches, ACI, ISE, and vCenter
Log-based reporting tools
Usually firewall logs only
Log analytics has its place for traffic forensics. But a configuration audit, what the rules are, whether they are clean, and who changed them, is what most firewall audits actually require, and that is what SAMURAI is built for. It does not run automated rule-recertification campaigns; it produces the analysis those workflows consume.
Frequently asked questions
What is a firewall audit tool?
A firewall audit tool reads firewall configuration and helps you verify it: what the rules permit, whether any are shadowed, redundant, or overly broad, and who changed them since the last review. SAMURAI does this from configuration state across Palo Alto, FortiGate, Cisco, and Juniper, and exports the evidence.
How do I audit firewall rules with it?
Register your firewalls; SAMURAI syncs their configuration and runs the Policy Analyzer over the rule base. You get shadowed, redundant, and overly broad findings, effective-access per rule, and a change timeline with admin attribution, all searchable and exportable. See the firewall audit checklist for the full workflow.
Is this a firewall log audit tool?
No, it audits configuration, not logs. It reads the rules, objects, and NAT from each device rather than parsing syslog, so you audit the policy itself and every change to it. For traffic-log forensics, pair it with a log platform.
Can it prove who changed a firewall rule?
Yes. Changes are detected from real device state and attributed to the admin (commit-correlated on PAN-OS, transaction-grouped on APIC, time-windowed on FortiOS/ISE/vCenter), so the audit trail names the author, not just the change.
Does it generate compliance reports?
It exports the rule inventory, hygiene findings, and change history to CSV, XLSX, HTML, or PDF, which is the evidence most audits need. It also runs 140+ CIS checks on Cisco IOS-XE, NX-OS, IOS-XR, and ASA. It does not produce framework-specific certification attestations.
Which firewalls can it audit?
Palo Alto (PAN-OS), FortiGate (FortiOS), Cisco FMC/FTD and ASA, and Juniper SRX (Junos OS), plus ACL visibility on Cisco routers, switches, and ACI fabrics.